{"id":"MAL-2026-17715","summary":"Malicious code in @brick-v2/core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (90c1fd9505ce4256620f9cb647e3a57a5af52539aa1e717a3eecb0485dec8c83)\nThe package's main entry `index.js` loads a prebuilt native binary at `prebuilds/\u003cplatform\u003e-\u003carch\u003e/metrics.node` inside a top-level try/catch, executing native code within the Node process as soon as the module is required. The ELF binary reads credential-grade environment variables including AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, and ACTIONS_ID_TOKEN_REQUEST_TOKEN, along with hostname, uid, and current working directory, and POSTs them as JSON to the hardcoded host `oob.s4yhii.com` via a raw socket (`POST /native HTTP/1.0`). The native code also invokes `fork`/`setsid` to detach from the parent process. The package is published as `@brick-v2/core` at version `999.0.1` with a trivial JS wrapper, a generic `core module` description, and `UNLICENSED` — a shape consistent with a dependency-confusion payload targeting a private `@brick-v2` scope so that npm resolution prefers this public version over an internal package.\n","modified":"2026-10-09T14:00:07.125906794Z","published":"2026-10-09T13:39:05Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-10-09T13:39:05Z","sha256":"13cc187815f5f1b0024df22bab31f1735b2bb864854af665422a8401a7672226","source":"amazon-inspector","versions":["999.0.2"],"id":"IN-MAL-2026-021309","import_time":"2026-10-09T13:46:18.836800095Z"},{"import_time":"2026-10-09T13:46:19.303415364Z","modified_time":"2026-10-09T13:39:53Z","sha256":"90c1fd9505ce4256620f9cb647e3a57a5af52539aa1e717a3eecb0485dec8c83","source":"amazon-inspector","versions":["999.0.1"],"id":"IN-MAL-2026-021315"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@brick-v2/core/v/999.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@brick-v2/core/v/999.0.1"}],"affected":[{"package":{"name":"@brick-v2/core","ecosystem":"npm","purl":"pkg:npm/%40brick-v2/core"},"versions":["999.0.2","999.0.1"],"database_specific":{"indicators":{"evidence_files":[{"path":"prebuilds/linux-x64/metrics.node","sha256":"daedefd6a8a02449e29a163a1a92edc0859c0cdb814ec1024b6615fa78bdd375","tlsh":"8272641bb261ce3bc4dc4278015b5ab0b1b25474e77353231b10a1ba3e927485ebaf9a"},{"path":"index.js","sha256":"28a4105532d31a66371b6137846227bf97a38d10f3c18833e3dabd535e6a5ee3","tlsh":"00f09ed97fa5b35a626676a8d66f015564ffc4f0042cbac4c448c9e127b09480e639fc"}],"package_integrity":[{"hashes":{"sha1":"d821df08e6706e25ae21685a64e310c86d29a051","sha512_sri":"sha512-LT2G7XVm0Gjx4js7K11mW0TLE/MS7y3qlPZMPRBhMrF02E0m/sl3r4o4mTVaDxxr/IRVUDtBG/0mbF8ZDMs8+Q=="},"filename":"core-999.0.2.tgz"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@brick-v2/core/MAL-2026-17715.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}